Data Processing Agreement
Version 3.0 — Valid from: 19 August 2026 (replaces version 2.0 of 28 January 2025)
This is an English translation of our Norwegian data processing agreement, available here. The Norwegian version is the governing version; in case of any discrepancy, the Norwegian version prevails.
1. Introduction and purpose
1.1 The purpose of this data processing agreement (the "Agreement") is to govern the parties' rights and obligations under the General Data Protection Regulation (EU) 2016/679 (the "GDPR") and applicable Norwegian law implementing the GDPR (hereinafter collectively referred to as the "Data Protection Legislation"), when the Data Processor processes personal data on behalf of the Data Controller.
1.2 The Data Controller uses WP's SaaS solution for property inspection and documentation in connection with:
- Inspection of residential properties (documentation of condition and/or damage)
- Renovation, conversion and extension (ROT) of residential properties (project documentation)
1.3 This Agreement forms an integral part of the parties' Subscription Agreement. In connection with the Data Processor's delivery of the Service under the Subscription Agreement, the Data Processor will process personal data on behalf of the Data Controller. In the event of a conflict between the Main Agreement and this Agreement, this Agreement shall take precedence for matters concerning the Data Processor's processing of personal data on behalf of the Data Controller.
1.4 The Data Processor shall only process personal data in accordance with this Agreement and any written instructions from the Data Controller.
1.5 The Customer is either a controller or a processor of the personal data processed under this Agreement. When the Customer is a controller, WP is a processor. When the Customer is a processor, WP is a sub-processor. This Agreement applies to both situations.
1.6 All rights granted to the Data Controller under this Agreement also apply to the Customer's customer when that entity acts as the legal controller of the personal data. Unless otherwise specified in this Agreement, or agreed in writing between the parties, WP shall, however, only be in direct contact with and follow instructions regarding the processing of personal data from the Customer.
1.7 Subject to amendments in accordance with section 17 below, this Agreement applies from the date set out above.
2. Definitions
2.1 Personal Data, Processing, Data Controller, Data Processor, Data Subjects, Personal Data Breach and Supervisory Authority shall have the meanings set out in the GDPR.
2.2 The Agreement refers to this document with appendices.
2.3 The Service refers to WP's SaaS solution, used by the Customer for inspections, image and LiDAR storage, quantity calculation and/or price estimation etc., in accordance with the Subscription Agreement.
3. Roles and responsibilities
3.1 The Data Controller determines the purposes and means of the processing of the personal data. The Data Controller is responsible for ensuring that the processing has a valid legal basis (e.g. consent or legitimate interest), and for otherwise complying with the requirements of the GDPR.
3.2 The Data Processor processes personal data on behalf of the Data Controller. The Data Processor undertakes to comply with the requirements of Article 28 of the GDPR and the provisions set out in this Agreement.
3.3 The Data Controller is responsible for informing end users (property owners, tenants, its own employees etc.), in accordance with the GDPR, that the Data Processor is used for the processing of personal data in accordance with this Agreement.
3.4 The Data Controller is further responsible for ensuring that no special categories of personal data/sensitive data are uploaded to the solution (including, but not limited to, images of health certificates or police certificates). The Data Processor shall facilitate that such data is not necessary for the fulfilment of the Service's purpose. The Data Controller shall, however, ensure compliance.
3.5 WP additionally processes certain personal data about the Customer's contact persons as a controller for its own purposes, including customer administration, invoicing and payment execution (among other things through Stripe, Tripletex and Attio, cf. Appendix 1). Such processing falls outside this Agreement and is described in WP's privacy policy.
4. Purpose, scope and duration of the processing activities
4.1 The categories of personal data and data subjects, the relevant processing activities, and the purpose and nature of the processing carried out by the Data Processor on behalf of the Data Controller are described in more detail in Appendix 1 to this Agreement.
5. The Data Controller's instructions
5.1 Instructions from the Data Controller
5.1.1 The Data Processor shall only process personal data in accordance with the Data Protection Legislation, and pursuant to written instructions from the Data Controller set out in this Agreement and in the Subscription Agreement. This means that the Data Processor shall not process personal data to a greater extent or for purposes other than what is necessary for the Data Processor to fulfil its obligations under the Data Protection Legislation, this Agreement and the Subscription Agreement.
5.1.2 The limitations set out above do not, however, apply to the extent that the Data Processor is obliged under EU/EEA law, or the law of an EU/EEA state, to process the personal data in another manner. If such an obligation arises, the Data Processor shall notify the Data Controller thereof, unless such notification would be contrary to the applicable legal basis.
5.1.3 If the Data Processor considers that an instruction is contrary to the GDPR or other legislation, the Data Processor shall inform the Data Controller as soon as possible.
6. Machine learning, anonymisation and pseudonymisation
6.1 Training of algorithms
6.1.1 The Data Processor may use anonymised and/or aggregated data as well as pseudonymised data in WP's SaaS solution for the development and improvement of the Service (e.g. improved quantity calculations, price estimates, image recognition etc.).
6.1.2 The Data Processor is the controller for this processing of personal data, and this processing of personal data thus falls outside the scope of this Agreement. The Data Processor is responsible for ensuring that such processing is carried out in accordance with the Data Protection Legislation.
6.1.3 The Data Processor's processing of anonymised data also falls outside the scope of the GDPR.
6.2 Product improvement and development
6.2.1 The Data Controller acknowledges that the Data Processor is free to use anonymised and/or aggregated as well as pseudonymised data in WP's SaaS solution for analysis and product development for the improvement of the Service.
6.2.2 The Data Processor is the controller for this processing of personal data, and this processing of personal data thus falls outside the scope of this Agreement. The Data Processor is responsible for ensuring that such processing is carried out in accordance with the Data Protection Legislation.
6.2.3 The Data Processor's processing of anonymised data also falls outside the scope of the GDPR.
7. Security measures
7.1 Technical and organisational measures
7.1.1 The Data Processor shall implement appropriate technical and organisational measures to ensure confidentiality, integrity and availability in accordance with the Data Protection Legislation.
7.1.2 The scope of the measures described above shall take into account the state of the art, the costs of implementation, and the nature, scope, purposes and context of the processing, as well as risk. Such measures may include access control, encryption, logging and procedures for handling incidents.
7.1.3 An overview of applicable security routines can be found in the Data Processor's own security document, which is made available to the Data Controller upon request.
7.2 Personal data breaches
7.2.1 In the event of a suspected or confirmed personal data breach (cf. Article 4(12) of the GDPR), the Data Processor shall notify the Data Controller without undue delay. The Data Processor shall further assist the Data Controller with the information necessary for the Data Controller to fulfil its notification obligations towards the Supervisory Authority and/or the data subjects, to the extent reasonable having regard to the nature of the processing and the information available to the Data Processor.
7.2.2 The Data Processor shall take reasonable measures to limit the consequences of the security breach.
8. Subcontractors (sub-processors)
8.1 General authorisation to use subcontractors
8.1.1 The Data Processor has the Data Controller's consent to engage subcontractors (sub-processors) to process or assist in processing personal data covered by this Agreement.
8.1.2 The Data Processor's subcontractors are listed in Appendix 1 to this Agreement. The Data Processor is responsible for the subcontractors' fulfilment of the requirements of this Agreement, as if they were the Data Processor's own actions.
8.1.3 The Data Processor shall ensure that subcontractors are subject to obligations equivalent to those imposed on the Data Processor under this Agreement.
8.2 Changes of subcontractors
8.2.1 The Data Processor will inform the Data Controller of changes in the use of subcontractors, so that the Data Controller is given the opportunity to object to the change.
8.2.2 The Data Controller must submit its objection to the Data Processor's notified use or replacement of a subcontractor within seven (7) days of the Data Controller receiving the relevant notice from the Data Processor. Such an objection may result in the Data Processor being unable to fulfil its obligations (or parts thereof) under the Subscription Agreement (without WP being held liable for this). The parties shall therefore loyally and in good faith attempt to find a satisfactory solution to the Data Controller's objection.
9. Transfer of personal data
9.1 Processing of personal data outside the EU/EEA
9.1.1 The Data Processor shall not transfer personal data to countries outside the EU/EEA unless the Data Controller has consented to such processing.
9.1.2 The Data Controller hereby gives the Data Processor its consent to such processing of personal data outside the EU/EEA, provided that:
- the Data Processor informs the Data Controller in advance that the Data Processor plans to transfer personal data outside the EU/EEA; and
- the Data Processor has a valid basis for such transfer in accordance with Chapter V of the GDPR.
9.1.3 Upon entering into the Agreement, the Data Controller consents to the transfers identified in Appendix 1.
9.1.4 The Data Controller has the right to object to such transfer if there are reasonable grounds to believe that the transfer in question will not satisfy the above requirements. If the Data Controller objects to the transfer, this may result in the Data Processor being unable to fulfil its tasks (or parts thereof) under the Subscription Agreement (without WP being held liable for this). The parties shall therefore loyally and in good faith attempt to find a satisfactory solution to the Data Controller's objection.
10. Assistance to the Data Controller
10.1 Rights of and requests from data subjects
10.1.1 If the Data Processor receives requests directly from data subjects, the Data Processor shall forward the request to the Data Controller without undue delay.
10.1.2 Upon request from the Data Controller, the Data Processor shall, to a reasonable extent, assist the Data Controller in responding to requests from data subjects.
10.2 The Data Processor's assistance
10.2.1 The Data Processor shall assist the Data Controller in complying with its obligations under the Data Protection Legislation, for example in the event of personal data breaches, the preparation of data protection impact assessments (DPIA) and contact with the Supervisory Authority, to the extent relevant to the Service.
11. Access and audits
11.1 Documentation
11.1.1 The Data Processor shall make the necessary documentation available to the Data Controller to demonstrate compliance with this Agreement and the Data Protection Legislation.
11.2 Audits
11.2.1 The Data Controller may, with reasonable notice and no more than once per year, require an audit or inspection of the Data Processor's compliance with this Agreement.
11.2.2 Such audit shall be carried out in a manner that does not unduly disrupt the Data Processor's ordinary business operations.
11.2.3 The Data Processor may require that the Data Controller enters into a confidentiality agreement with the Data Processor before the Data Processor grants access or enables an audit under this section 11.
12. Duty of confidentiality
12.1 Confidentiality
12.1.1 The Data Processor shall ensure that all employees or subcontractors who process personal data under this Agreement are subject to a duty of confidentiality, and shall oblige them to treat the data confidentially.
13. Duration and termination
13.1 Duration of the Agreement
13.1.1 This Agreement applies for as long as the Data Processor processes personal data on behalf of the Data Controller for the purposes described in this Agreement and in the Subscription Agreement.
13.1.2 The Data Processor is not entitled to store or otherwise process personal data after the expiry of the Agreement, unless the Data Processor is subject to such an obligation under mandatory legislation.
14. Deletion and return of data
14.1 Return and deletion
14.1.1 Upon expiry of the Agreement or upon written request from the Data Controller, the Data Processor shall delete or return all personal data.
14.1.2 Unless otherwise agreed, the Data Processor deletes all personal data no later than 30 days after the expiry of the Agreement. During this period, the Data Controller may export data.
15. Privacy contact point
15.1 Enquiries
15.1.1 The Data Processor can be contacted by e-mail at hello@wennproperty.no for questions or requests regarding privacy and data processing.
16. Liability and compensation
16.1 Allocation of liability
16.1.1 The parties' liability for damage affecting the data subject or other natural persons caused by a breach of the Data Protection Legislation follows the provisions of Article 82 of the GDPR.
16.1.2 The parties are each individually liable for administrative fines imposed pursuant to Article 83 of the GDPR.
16.2 Coverage of costs
16.2.1 The Data Processor may claim reasonable compensation for assistance to the Data Controller under sections 10 and 11 above. The Data Processor's right to claim compensation for assistance in connection with audits applies only to the extent that the relevant audit does not reveal material breach on the part of the Data Processor.
17. Changes and updates
17.1 Updating the Agreement
17.1.1 The Data Processor may update this Agreement in the event of changes to applicable Data Protection Legislation. Material changes shall be notified to the Data Controller within a reasonable time.
17.1.2 The Data Processor may also update the Agreement from time to time in order to (a) reflect agreed changes to the Customer's instructions or to accommodate changes to WP's Services; or (b) reflect changes to the processing carried out in accordance with sections 8 and 9 of the Agreement.
18. Governing law and dispute resolution
18.1 Governing law
18.1.1 The Agreement is governed by and shall be interpreted in accordance with Norwegian law.
18.2 Dispute resolution
18.2.1 Any disputes between the parties shall be sought resolved amicably. If the parties do not succeed, the matter may be brought before the ordinary courts, with the court of WP's registered business address at any given time as the legal venue, unless otherwise required by mandatory legislation.
19. Appendices
Further details on the categories of personal data, the purpose of the processing, the use of subcontractors, and other relevant information are set out in Appendix 1 to this Agreement.
Appendix 1: Description of the Processing
This Appendix 1 forms an integral part of the Agreement and describes the processing of personal data that the Data Processor will carry out on behalf of the Data Controller.
Categories of personal data
- Contact data: Name, e-mail, phone number, address, and where applicable position/title
- Property data: Residential/property addresses, cadastral numbers, images of interiors/exteriors, 3D scans (LiDAR)
- Project information: Work orders, work descriptions, documentation of renovation, inspection, planning, cost calculations/quotes
- Special categories of personal data: No special categories of personal data will be processed in connection with this Agreement.
Categories of data subjects
- Property owners, tenants, other residents/customers (private homeowners or professional property managers)
- Employees of the Data Controller (e.g. project managers, technical personnel)
- Other relevant third parties if the Data Controller enters their data into the Service
Purpose and nature of the processing
The Data Processor shall deliver the Service to the Customer, i.e. a digital solution for the fulfilment of the following purposes:
- Property inspection: Documentation of condition and any deviations at move-in and move-out, as well as in ROT projects.
- Cost estimation and quotes: Use of data to calculate quantities, prices and the basis for quotes.
The processing will include the processing activities necessary to fulfil the purpose described in this Appendix 1, including the following processing of personal data: collection, registration, sharing, storage, structuring and analysis. Certain processing activities are carried out wholly or partly automatically. Additional processing activities may also be carried out according to the Data Controller's instructions.
Storage location and subcontractors
Storage location: Microsoft Azure. Personal data processed under the Agreement is stored and processed primarily in Norway, secondarily in Sweden, and always within the EU/EEA.
Sub-processors:
- Microsoft Azure (cloud service — operation and storage of the Service). Processing location: primarily Norway, secondarily Sweden, EU/EEA only.
- Stripe Payments Europe, Ltd. (Ireland — payment processing and subscription billing). Processing location: EU/EEA; data relating to payment transactions may be transferred to Stripe, LLC (USA) and Stripe's sub-processors in third countries, with a transfer basis in the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses (SCCs), cf. section 9 of the Agreement.
- Tripletex AS (Norway — accounting and invoicing, including EHF). Processing location: Norway/EU/EEA.
- Attio Ltd. (United Kingdom — customer administration/CRM). Processing location: EU (Google Cloud EMEA); the United Kingdom is covered by the European Commission's adequacy decision.
Stripe, Tripletex and Attio only process data relating to the Customer's account, payment and invoicing. They do not have access to the Customer's project data, reports, images or scans stored in the Service. Payment card details are provided by the cardholder directly to Stripe and are never stored in, and are not accessible to, WP's systems. Stripe is certified under PCI DSS Level 1.
Storage period
- Storage: Until the Customer deletes the data.
- After expiry: Data is deleted within 30 days of expiry, with the Customer having the opportunity to export data during this period.